
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@haimkastner/workforce-ai-mcp
Advanced tools
MCP server for Workforce AI — policy management, asset visibility, and apps catalog via LLM tool calls
Pre-release disclaimer: This package is currently in release candidate (RC) stage and is intended for testing and evaluation purposes only. APIs and tool definitions may change before the stable release. Do not use in production environments.
An MCP (Model Context Protocol) server that exposes Check Point Workforce AI capabilities as LLM tools — enabling AI assistants to query, analyze, and manage AI & Browse security policies, assets, and applications through natural language.
For more information, see Infinity Portal Administration Guide.
| Region | Gateway URL |
|---|---|
| Europe | https://cloudinfra-gw.portal.checkpoint.com |
| United States | https://cloudinfra-gw-us.portal.checkpoint.com |
| Variable | Required | Description |
|---|---|---|
CP_CI_CLIENT_ID | Yes | CloudInfra API key client ID |
CP_CI_ACCESS_KEY | Yes | CloudInfra API key secret |
CP_CI_GATEWAY | Yes | CloudInfra gateway URL |
MCP_MODE | Yes | Transport mode: stdio or http |
PORT | When http | HTTP server port |
WRITE_MODE | No | Set to true to enable write tools (default: false). Warning: enabling write mode allows the LLM to create, modify, and delete security policy rules. Use with caution. |
Use stdio mode when connecting directly from an MCP client such as Claude Desktop, VS Code, or Cursor:
CP_CI_CLIENT_ID="your-client-id" \
CP_CI_ACCESS_KEY="your-access-key" \
CP_CI_GATEWAY="https://cloudinfra-gw-us.portal.checkpoint.com" \
MCP_MODE=stdio \
npx @haimkastner/workforce-ai-mcp
Add to your claude_desktop_config.json:
{
"mcpServers": {
"workforce-ai": {
"command": "npx",
"args": ["--yes", "@haimkastner/workforce-ai-mcp"],
"env": {
"CP_CI_CLIENT_ID": "your-client-id",
"CP_CI_ACCESS_KEY": "your-access-key",
"CP_CI_GATEWAY": "https://cloudinfra-gw-us.portal.checkpoint.com",
"MCP_MODE": "stdio"
}
}
}
}
Use HTTP mode when running the server as a standalone service:
CP_CI_CLIENT_ID="your-client-id" \
CP_CI_ACCESS_KEY="your-access-key" \
CP_CI_GATEWAY="https://cloudinfra-gw-us.portal.checkpoint.com" \
MCP_MODE=http \
PORT=3000 \
npx @haimkastner/workforce-ai-mcp
The server exposes:
POST /mcp — MCP StreamableHTTP endpointGET /health — Health checkBy default, the server starts in read-only mode, exposing tools for querying and analyzing policies without making any changes. This is safe for exploration and auditing.
To enable write operations, set WRITE_MODE=true. This unlocks tools that modify the policy configuration:
| Tool | Description | Mode |
|---|---|---|
list_chats_rules | List all Chats (GenAI DLP) rules. | read |
list_ai_access_rules | List all AI Access rules that control which AI services and applications users are allowed to interact with. | read |
list_web_access_rules | List all Web Access rules for Browse Security. | read |
list_agents_rules | List all Agents (MCP Server) rules that govern agent interactions. | read |
list_secure_browsing_rules | List all Secure Browsing threat-prevention rules. | read |
list_dlp_rules | List all Browse DLP (Data Loss Prevention) rules for browser security. | read |
set_rule_info | Update the display name and description of a rule identified by its UUID. | write |
set_rule_active | Enable or disable a rule without deleting it. | write |
reorder_rule | Move a rule to a new position in the rulebase. | write |
delete_rule | Permanently delete a rule from the rulebase by its UUID. | write |
create_chats_rule | Create a new Chats (GenAI DLP) rule. | write |
create_ai_access_rule | Create a new AI Access rule that controls which AI services and applications users can interact with. | write |
create_agents_rule | Create a new Agents (MCP Server) rule that governs agent interactions. | write |
create_dlp_rule | Create a new Browse DLP rule for data loss prevention during web browsing. | write |
create_secure_browsing_rule | Create a new Secure Browsing threat-prevention rule. | write |
list_file_protection_objects | List all file-protection policy objects. | read |
list_domains_objects | List all domains policy objects. | read |
get_tenant_dlp_datatypes | Get the tenant-specific DLP datatype configuration showing which data types are currently enabled for detection in this tenant's policies.. | read |
search_dlp_datatypes | Search DLP data types by name or description with pagination. | read |
analyze_shadow_rules | Find unreachable (shadowed) rules in a rulebase. | read |
resolve_matching_rule | Given a user and target, determine which rule in the rulebase would apply. | read |
search_assets | Search deployed assets (endpoints/devices) with optional filtering, sorting, text search, and pagination. | read |
count_assets | Get the total count of deployed assets, optionally filtered. | read |
search_users | Search users in the organization with optional text search and pagination. | read |
search_apps | Search the GenAI apps catalog by name, description, or URL. | read |
get_apps_by_ids | Get specific GenAI apps from the catalog by their numeric IDs. | read |
In case of an issue or a bug found in the MCP server, please open an issue.
FAQs
MCP server for Workforce AI — policy management, asset visibility, and apps catalog via LLM tool calls
We found that @haimkastner/workforce-ai-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.